Exploited Known exploited (KEV) CVE-2020-11651

SaltStack Salt authentication bypass (CVE-2020-11651) — part of the batch listed the day the catalog opened, with 181 days allowed

SaltStack Salt Added to KEV Nov 3, 2021 Federal remediation due 2022-05-03

A flaw at the center of a system that pushes configuration to many servers at once, where some functions can be reached without authentication. It belongs to the batch listed on the day the catalog opened, with about half a year allowed, and its description carries an unusual line saying that users following basic practice are unaffected.

Key facts

  • CVE IDCVE-2020-11651
  • Affected (vendor / product)SaltStack Salt
  • ExploitationListed in CISA KEV (exploitation confirmed)
  • Remediation due2022-05-03 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • A flaw at the center of a configuration distribution system, where calls are not validated properly and some functions are reachable without authentication.
  • It is described as usable to obtain tokens held at the center or to run commands on the machines below.
  • It belongs to the bulk listing of 3 November 2021 and carries an allowance of 181 days, shared by 238 of the 1,694 records this site holds as of 2026-09-04.
  • The description closes with an unusual line placing users who follow fundamental guidance and established practice outside its scope.
  • No weakness classification is recorded for this entry, as with 175 (10.3%) of those same 1,694 records.

1Standing where distribution happens

Salt exists to push configuration and commands out to many servers at once. A central component sends instructions to the receivers running on each machine. As the catalog describes it, part of that center does not validate calls properly, and some functions can be reached without authenticating. What is reachable includes user tokens and a means of running commands on the machines below.

A system built to distribute is valuable because it can reach everywhere, and once taken, its reach is the same reach.

2A layer created by the first listing

  1. 1The catalog opensOn 3 November 2021 a large number of entries are listed together
  2. 2The allowanceDeadlines for that layer are set about half a year out, at 181 days
  3. 3AfterwardsEntries added individually settle on 21 days as the standard
  4. 4TodayOf the 1,694 records this site holds as of 2026-09-04, 238 carry an allowance of 181 days

The 181 days here is neither punishment nor leniency; it comes from the bulk listing that opened the catalog. Once operation settled into routine, 21 days became standard, a value shared by 1,025 entries. Read the number alone and this looks like a mild entry granted half a year. The meaning of a deadline does not come through until you check when the entry was listed.

3An unusual line in the description

Entries with an allowance of 181 days among the 1,694 this site holds as of 2026-09-04238The initial bulk listing
Entries with an allowance of 21 days, of those same 1,6941,025The standard under routine operation
Entries with no weakness classification recorded, of those same 1,69417510.3% of the total

This description ends by saying that users who follow fundamental guidelines and best practices are not affected. Catalog descriptions normally state what can happen and stop there. Conditionally denying impact is rare, and read the other way it suggests the flaw bites where the center has been placed somewhere reachable. The catalog does not spell out that condition.

4Sometimes the classification is simply absent

No weakness classification is recorded for this entry. Among those same 1,694 records, 175 (10.3%) are the same. Without a classification there is no way to search sideways for the same kind of weakness, and each case has to be handled on its own. Confirmed exploitation can settle first and classification arrive later. Being listed and being organized are different things.

Why it matters

A system built to push configuration everywhere has a compromise radius equal to its reach. The privilege held at such a center and how little it is thought about are rarely in proportion. Deadlines, too, have to be read together with when an entry was listed: the same catalog means different things for the opening batch and for routine operation.

FAQ

Why is the allowance 181 days?
It belongs to the batch listed when the catalog opened on 3 November 2021. Under routine operation the standard became 21 days, shared by 1,025 entries.
Are basic precautions enough?
The description carries a line to that effect, but it does not spell out the condition. Applicability should be confirmed with vendor sources and against your own environment.
Why is there no classification?
No reason is recorded. Confirmed exploitation can settle before a classification is assigned; 10.3% of entries are in the same position.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#Vulnerabilities#KEV#Security#Configuration management#Authentication bypass
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.